AI AUTOMATION • REAL ENGINEERING • YOU OWN IT

Checklist

AI Compliance & Governance Checklist

A structural self-check, not a certification. These are the questions we see skipped most often when an AI or automation system ships fast — data mapping, retention, residency, access control, human review, and what your model provider actually does with your data.

Data mapping

  • Can you name every system this data passes through, from entry to storage to any AI model call?
  • Do you know which fields are personal, sensitive, or regulated versus which are not?
  • Is there a diagram or document of this, or does it only exist in someone's head?

Retention and deletion

  • How long is data kept at each stage — including logs, model provider caches, and backups?
  • If someone asks you to delete their data, can you actually find and remove all of it?
  • Are retention periods a deliberate decision, or just whatever the default happened to be?

Data residency

  • Do you know which country/region your data (and any AI provider's processing of it) physically resides in?
  • Does that matter for your specific regulatory environment, and has anyone actually checked?

Access control

  • Who — people and systems — can actually see this data today, and is that list current?
  • Is there an audit log of who accessed what, or would you be guessing if asked?
  • Are AI model API keys and credentials scoped narrowly, or shared broadly for convenience?

Human-in-the-loop

  • For any AI-driven decision with real consequences, is there an explicit human review step?
  • Is there a way for someone affected by an AI decision to contest it or reach a person?
  • Is escalation a designed path, or does it only happen if someone happens to notice a problem?

Vendor and model-provider questions

  • Does your AI model provider train on your data by default, and have you actually checked the setting rather than assumed?
  • What does your provider's data processing agreement actually say about retention and subprocessors?
  • If you switched providers tomorrow, could you get your data out cleanly?

Documentation and auditability

  • Could you produce a written answer to 'how does this system handle our data' if a customer, auditor, or regulator asked tomorrow?
  • Is that documentation current, or does it describe an earlier version of the system?

This checklist exists because of a real, named pattern we see repeatedly — The Compliance Blind Spot. If any section above raised more questions than answers, that's the signal an AI Strategy & Audit is worth doing before (or alongside) a build.

FAQs

Is this a legal compliance certification (SOC 2, ISO 27001, GDPR, etc.)?

No — this is a structural self-check for the questions that get skipped when a system ships fast, not a substitute for a qualified compliance audit or legal review. If you need certification-level assurance, that's a different, formal process with its own specialists — see our Compliance Frameworks reference for what each specific framework actually requires.

We're a small team — does this actually apply to us?

The questions scale down fine. A two-person team building an internal tool still benefits from knowing where data goes and whether an AI provider trains on it by default — it's just a shorter answer, not a skipped one.

What's the most commonly skipped item on this list?

Checking the AI model provider's actual data-training default, rather than assuming it doesn't train on your data. Most providers publish this clearly, but almost nobody reads it before integrating — see our Compliance Blind Spot failure pattern for how this plays out.

Have a project in mind?

Tell us what you're trying to automate or build — we'll reply with next steps, not a sales pitch.